The package is small and clearly structured, with MIT licensing, a linked organization repository, and no install-time scripts. Limited testing and security-process evidence make long-term support harder to judge.
58%
Total Score
75
100
75
75
The repository has no tests or changelog, and this release has no release-notes excerpt. The compact source tree is coherent, but verification and change-history evidence are limited.
Only three releases have been published, with no release in the last 12 months and a median interval of about 18 months. That makes maintenance continuity a meaningful concern.
The repository recorded zero commits and zero active maintainers in the last 3 months. This weakens evidence of active maintenance, although the repository is not archived.
Composer build tooling is present, but no security-scanning tooling was detected. That leaves less evidence of automated security maintenance for this security-focused package.
The linked repository has no security policy. For a security component, that is a meaningful transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.